[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Vulnerability in site leads to source code dump
- To: "fulldisclosure@xxxxxxxxxxxx" <fulldisclosure@xxxxxxxxxxxx>
- Subject: [FD] Vulnerability in site leads to source code dump
- From: "Johnny Five" <hax0r892374@xxxxxxxx>
- Date: Wed, 1 Apr 2015 14:10:38 +0200
<html><head></head><body><div style="font-family: Verdana;font-size:
12.0px;"><div>
<pre>/__/\ /__/\ /_______/\ /_____/\ /___/\/__/\
/_____/\ /_____/\
\::\ \\ \ \\::: _ \ \\:::__\/
\::.\ \\ \ \\::::_\/_\:::_ \ \
\::\/_\ .\ \\::(_) \ \\:\ \
__\:: \/_) \ \\:\/___/\\:\ \ \
\
\:: ___::\ \\:: __ \ \\:\
\/_/\\:. __ ( ( \::___\/_\:\ \ \ \
\: \ \\::\ \\:.\ \ \
\\:\_\ \ \\: \ ) \ \
\:\____/\\:\/.:| |
\__\/ \::\/ \__\/\__\/ \_____\/
\__\/\__\/ \_____\/ \____/_/
_______ __ __
/_______/\ /_/\/_/\
\::: _ \ \\ \ \ \ \
\::(_) \/_\:\_\ \ \
\:: _ \ \\::::_\/
\::(_) \ \ \::\ \
__\_______\/__\__\/______ ______ ______ ______ ______
______ ______ ______
/_______/\ /_____/\ /_____/\ /_____/\ /_____/\ /_____/\
/_____/\ /_____/\ /_____/\ /_____/\
\::: _ \ \\::::_\/_\:::_ \ \\:::_:\
\\:::_ \ \\:::_ \ \\:::_ \
\\::::_\/_\:::_:\ \\:::__\/
\::(_) \/_\:\/___/\\:\ \ \
\\:\_\:\ \\:\ \ \ \\:\
\ \ \\:\ \ \ \\:\/___/\
/_\:\ \\:\ \ __
\:: _ \ \\:::._\/ \:\ \ \
\\::__:\ \\:\ \ \ \\:\ \ \
\\:\ \ \ \\_::._\:\ \::_:\
\\:\ \/_/\
\::(_) \ \\:\ \ \:\/.:| |
\ \ \\:\_\ \ \\:\_\ \
\\:\_\ \ \ /____\:\/___\:\
'\:\_\ \ \
\_______\/ \_\/ \____/_/ \_\/
\_____\/ \_____\/ \_____\/ \_____\/\______/
\_____\/
</pre>
<div> </div>
<div>We are BFD9000Sec and we have a mini dump surprise for you all! Website
comprimise leads to SOURCE CODE RELEASE!</div>
<div>Website target: http://www.0xrage.com</div>
<div>Source code: rcrypt packer</div>
<div> </div>
<div>LFI/RFI fail in module
donate.php?sendcash=[vulnerable]&donationfrom=[doesntmatter]</div>
<div> </div>
<div>User input not sanitized at all and now your c0de is d|_|mped!
Maybe stop using vulnerable WP plugins? lol</div>
<div> </div>
<div>We h0pe u enj0y the rel3ase!</div>
<div> </div>
<div> - BFD9000Sec!!!!</div>
<div> </div>
</div></div></body></html>
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/